Host Header Routing Bypass in http4k by 36g
CVE-2026-100724
6.3MEDIUM
What is CVE-2026-100724?
The http4k library contains a vulnerability where functions responsible for routing requests to virtual hosts can be exploited. When configured with two or more virtual hosts, an attacker can manipulate the Host header in HTTP requests, causing the server to incorrectly route to a different virtual host. This bypasses the intended authorization checks, allowing unauthorized access to potentially sensitive resources on the targeted application. It's crucial for users running affected versions to upgrade to the latest releases to mitigate these risks.
Affected Version(s)
http4k 0 < 6.49.0.0
http4k 0 < 5.42.0.0
http4k 0 < 4.51.0.0
